MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c3b6afc692a2e41d98070148d1d7e6cc1c5a0a6e154e4fb7359c89e158cc1a8c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c3b6afc692a2e41d98070148d1d7e6cc1c5a0a6e154e4fb7359c89e158cc1a8c
SHA3-384 hash: be6b3ac5606de17d3a7b0bd0edd58af7c4f38dc0432ac7713f3d57de8af1ab2a182e752795ab173b4379d8d363cf5b38
SHA1 hash: 60372c377b94a4b8d1dcae92abb709ac744e8011
MD5 hash: 8291a8a1226dc6c0bc6040a12fd40545
humanhash: stream-wyoming-maine-seventeen
File name:RFQ 097663899.zip
Download: download sample
Signature AgentTesla
File size:389'971 bytes
First seen:2020-07-07 08:24:42 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:8gzpQWXSVqbhUMPx96+YzrdzhJRJ1hCgZxEH8xV47Jbra2DnummuoPCh:rRSVqFc3VhJRjhCgZ+HOGLumm9G
TLSH DC84234EC9D711D6ADC10B48A3B661A3AB2982AFC115D7B734CEA9F830717A56F00793
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: molex.com
Sending IP: 103.99.1.149
From: Jessie Yang <sales@molex.com>
Subject: RE:PO - RFQ # 097663899 NEW ORDER
Attachment: RFQ 097663899.zip (contains "RFQ # 097663899.exe")

AgentTesla SMTP exfil server:
mail.pptoursperu.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-07 08:26:12 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip c3b6afc692a2e41d98070148d1d7e6cc1c5a0a6e154e4fb7359c89e158cc1a8c

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments